Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
1256 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.1) | 0.24% | — | Vmware Reactor NettyAI | 9/6/2026 | 23/7/2026 | In specific scenarios involving HTTP redirects from a secure to an insecure endpoint, the Reactor Netty HTTP client may leak credentials. In order for this to happen, the HTTP client must have been explicitly configured to follow redirects. Affected versions: Reactor Netty 1.0.0 through 1.0.51; 1.1.0 through 1.1.35;… | |
| Analizada | Alta (7.5) | 0.46% | — | Vmware Spring Hateoas | 9/6/2026 | 23/7/2026 | Spring HATEOAS maintains an unbounded static cache of StringLinkRelation instances keyed on attacker-supplied strings. Affected versions: Spring HATEOAS 1.5.0 through 1.5.6; 2.3.0 through 2.3.4; 2.4.0 through 2.4.1; 2.5.0 through 2.5.2; 3.0.0 through 3.0.3. | |
| Analizada | Alta (7.5) | 0.43% | — | Vmware Spring Hateoas | 9/6/2026 | 23/7/2026 | Spring HATEOAS's internal PropertyUtils.createObjectFromProperties method, used by the Collection+JSON and UBER media type deserializers, performs bean property binding via reflection without consulting Jackson access-control annotations. Affected versions: Spring HATEOAS 1.5.0 through 1.5.6; 2.3.0 through 2.3.4;… | |
| Analizada | Media (5.4) | 0.32% | — | Vmware Aria OperationsVmware Cloud FoundationVmware Telco Cloud Platform | 8/6/2026 | 23/7/2026 | VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies, views or text-widgets may be able to inject scripts to perform administrative actions in VMware Cloud Foundation Operations. | |
| Analizada | Alta (8) | 0.42% | — | Vmware Aria OperationsVmware Cloud FoundationVmware Telco Cloud PlatformVmware Vsphere | 8/6/2026 | 23/7/2026 | VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies, views or text-widgets may be able to inject scripts to perform administrative actions in VMware Cloud Foundation Operations. | |
| Analizada | Media (5.4) | 0.32% | — | Vmware Aria OperationsVmware Cloud FoundationVmware Telco Cloud PlatformVmware Vsphere | 8/6/2026 | 23/7/2026 | VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies, views or text-widgets may be able to inject scripts to perform administrative actions in VMware Cloud Foundation Operations. | |
| Analizada | Media (6.5) | 0.28% | — | Vmware Spring Cloud Function | 1/6/2026 | 22/7/2026 | OOM error is possible while attempting to add infinite amount of functions to Function Registry. Affected Spring Products and Versions: Spring Cloud Function 3.2.x: versions prior to 3.2.16 Spring Cloud Function 4.1.x: versions prior to 4.1.10 Spring Cloud Function 4.2.x: versions prior to 4.2.6 Spring Cloud Function… | |
| Analizada | Media (6.5) | 0.28% | — | Vmware Spring Cloud Function | 1/6/2026 | 22/7/2026 | Under infinite recursion in the routing layer, request-handling can cause OOM error. Affected Spring Products and Versions: Spring Cloud Function 3.2.x: versions prior to 3.2.16 Spring Cloud Function 4.1.x: versions prior to 4.1.10 Spring Cloud Function 4.2.x: versions prior to 4.2.6 Spring Cloud Function 4.3.x:… | |
| Analizada | Media (6.5) | 0.41% | — | Vmware Spring AI | 25/5/2026 | 23/7/2026 | Spring AI's support for Anthropic's Skills API used LLM-influenced filenames unsanitized in Path.resolve before writing files to disk. This could allow a malicious user to write files outside the intended target directory, including restricted directories. Affected versions: Spring AI: 1.1.0 through 1.1.x | |
| Analizada | Alta (7) | 0.11% | — | Vmware Fusion | 15/5/2026 | 17/6/2026 | VMware Fusion contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during an operation performed by a SETUID binary. A malicious actor with local non-administrative user privileges may exploit this vulnerability to escalate privileges to root on the system where Fusion is installed. | |
| Aplazada | Media (6.3) | 0.27% | — | Vmware Cloud AWSAI | 14/5/2026 | 17/6/2026 | Spring Cloud AWS simplifies using AWS managed services in a Spring and Spring Boot applications. From 3.0.0 to 4.0.1, pplications using Spring Cloud AWS SNS HTTP/HTTPS endpoint support (@NotificationMessageMapping, @NotificationSubscriptionMapping, @NotificationUnsubscribeConfirmationMapping) did not verify the… | |
| Pendiente de análisis | Alta (7.2) | 0.10% | — | Vmware EsxiAI | 13/5/2026 | 7/10/2026 | An untrusted pointer dereference in the ionic cloud driver for VMWare ESXi could allow an attacker with an unprivileged VM to read kernel memory or co-located guest VM memory, potentially resulting in loss of confidentiality or availability. | |
| Pendiente de análisis | Alta (8.8) | 0.11% | — | Vmware EsxiAI | 13/5/2026 | 7/10/2026 | A heap-based buffer overflow in the ionic cloud driver for VMware ESXi could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution. | |
| Pendiente de análisis | Alta (8.8) | 0.10% | — | Vmware EsxiAI | 13/5/2026 | 7/10/2026 | A heap-based buffer overflow in the ionic cloud driver for VMware ESXi could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution. | |
| Pendiente de análisis | Alta (8.3) | 0.12% | — | Intel Data Center Graphics DriverAIVmware EsxiAI | 12/5/2026 | 17/6/2026 | Out-of-bounds write for the Intel(R) Data Center Graphics Driver for VMware ESXi software before version 2.0.2 within Ring 1: Device Drivers may allow a denial of service. System software adversary with a privileged user combined with a low complexity attack may enable data corruption. This result may potentially… | |
| Pendiente de análisis | Crítica (9.3) | 0.13% | — | Intel Data Center Graphics DriverAIVmware EsxiAI | 12/5/2026 | 17/6/2026 | Buffer overflow for the Intel(R) Data Center Graphics Driver for VMware ESXi software before version 2.0.2 within Ring 1: Device Drivers may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable local code execution. This result may… | |
| Pendiente de análisis | Alta (8.3) | 0.12% | — | Intel Data Center Graphics DriverAIVmware EsxiAI | 12/5/2026 | 17/6/2026 | Out-of-bounds read for the Intel(R) Data Center Graphics Driver for VMware ESXi software before version 2.0.2 within Ring 1: Device Drivers may allow a denial of service. System software adversary with a privileged user combined with a low complexity attack may enable data exposure. This result may potentially occur… | |
| Analizada | Alta (8.2) | 0.35% | — | Vmware Spring AI | 12/5/2026 | 17/6/2026 | A malicious user could craft input that is stored in conversation memory and later interpreted by the model in an unintended way. Applications using the affected advisor with user-controlled input may be susceptible to manipulation of model behavior across conversation turns. | |
| Analizada | Alta (7.5) | 0.41% | — | Vmware Spring AI | 12/5/2026 | 17/6/2026 | Spring AI's chat memory component contained a problematic default that, when not explicitly overridden, could result in unintended data exposure between users. | |
| Pendiente de análisis | Crítica (9.6) | 0.62% | — | SAP Commerce CloudAIVmware SecurityAI | 12/5/2026 | 17/6/2026 | Due to improper Spring Security configuration, SAP Commerce Cloud allows an unauthenticated user to perform malicious input injection, resulting in arbitrary server-side code execution, leading to high impact on Confidentiality, Integrity, and Availability of the application. | |
| Analizada | Alta (8.6) | 0.39% | — | Vmware Spring AI | 9/5/2026 | 24/7/2026 | Spring AI's MilvusVectorStore#doDelete(List) implementation is vulnerable to filter-expression injection via unsanitized document IDs. Spring AI 1.0.x: affected from 1.0.0 through latest 1.0.x; upgrade to 1.0.7 or greater. Spring AI 1.1.x: affected from 1.1.0 through latest 1.1.x; upgrade to 1.1.6 or greater. | |
| Analizada | Media (4.4) | 0.16% | — | Vmware Spring Cloud Config | 7/5/2026 | 17/6/2026 | When enabling trace logging in Spring Cloud Config Server sensitive information was placed in plain text in the logs. Spring Cloud Config 3.1.x: affected from 3.1.0 through 3.1.13 (inclusive); upgrade to 3.1.14 or greater (Enterprise Support Only). Spring Cloud Config 4.1.x: affected from 4.1.0 through 4.1.9… | |
| Analizada | Alta (8.1) | 0.22% | — | Vmware Spring Cloud Config | 7/5/2026 | 17/6/2026 | The base directory (`spring.cloud.config.server.git.basedir`) used by the Spring Cloud Config Server to clone Git repositories to is susceptible to time-of-check-time-of-use (TOCTOU) attacks. Spring Cloud Config 3.1.x: affected from 3.1.0 through 3.1.13 (inclusive); upgrade to 3.1.14 or greater (Enterprise Support… | |
| Modificada | Crítica (9.1) | 0.82% | 💥 PoC | Vmware Spring Cloud Config | 7/5/2026 | 15/7/2026 | Spring Cloud Config allows applications to serve arbitrary text and binary files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lead to a directory traversal attack. Spring Cloud Config 3.1.x: affected from 3.1.0 through 3.1.13… | |
| Modificada | Alta (7.5) | 0.48% | — | Vmware Spring Cloud Config | 7/5/2026 | 15/7/2026 | When using Google Secrets Manager as a backend for the Spring Cloud Config server a client can craft a request to the config server potentially exposing secrets from unintended GCP projects. Spring Cloud Config 3.1.x: affected from 3.1.0 through 3.1.13 (inclusive); upgrade to 3.1.14 or greater (Enterprise Support… |